← All articles

Checklist · 2026-07-12

WordPress Security Checklist (30 Steps for 2026)

A checklist beats good intentions. This 30-step WordPress security checklist for 2026 is grouped so you can work through it in an afternoon and close the gaps behind almost every WordPress hack — from updates and login to file permissions, headers and monitoring.

Baseline your site first: run a free MageArgus scan to see versions, exposed files and headers, then tick off the rest below.

By the numbers
  • Updates + login hardening prevent the majority of real WordPress compromisesWPScan / Sucuri
  • Blocking PHP in uploads neutralises the most common backdoor locationMageArgus

Updates & components

Login & users

wp-config & files

Transport & headers

Backups & monitoring

Hosting & extras

Deep-dive on the trickiest items in wp-config hardening.

Frequently asked questions

How often should I run through this checklist?

Do the full pass once, then re-check updates weekly and revisit the whole list quarterly and after any major change. Backups and monitoring should run continuously.

Which items matter most?

Updates, two-factor auth, blocking PHP in uploads, and tested backups. Those four alone stop or contain most WordPress attacks; the rest reduce your remaining exposure.

Related reading

Scan your store free →